METHOD FOR ACCELERATING CRYPTOGRAPHIC OPERATIONS 
ON ELLIPTIC CURVES 
This invention relates to a method for performing computations in cryptographic systems 
utilizing elliptic curves. 
5 This application is a continuation-in-part of United States Patent Application No* 

09/885,959, filed on June 22, 2001, which is a continuation of International Application No. 
PCT/CA99/01222, filed on December 23, 1999, and claims the priority of Canadian Patent 
Application No- 2,257,008, filed on December 24, 1998, the content of all of which is 
incorporated herein by reference* 
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BACKGROUND OF THE INVENTION 
O A public-key data communication system may be used to transfer information between a 

pair of correspondents. At least part of the information exchanged is enciphered by a 
UJ predetermined mathematical operation by the sender and the recipient may perform a 
1 5q complementary mathematical operation to decipher the information. 
fT Each correspondent has a private key and a public key that is mathematically related to 

s the private key. The relationship is such that it is not feasible to determine the private key from 
52 knowledge of the public key. The keys are used in the transfer of data, either to encrypt data that 
H* is to be transferred or to attach a signature to allow verification of the authenticity of the data. 
2Xf% * For encryption, one correspondent uses the public key of the recipient to encrypt the 
^ message and sends it to the recipient, The recipient then uses her private key to decipher the 

message. 

A common key may also be generated by combining one parties public key with the other 
parties private key. It is usual in such cases to generate new private and corresponding public 
25 keys for each communication session, usually referred to as session keys or ephemeral keys, to 
avoid the long-term keys of the parties being compromised. 

The exchange of messages and generation of the public keys may therefore involve 
significant computation involving exponentiation when the cryptographic system utilizes in Z*p, 
the finite field of integers mod p where p is a prime or the analogous operation of point 
30 multiplication when the system utilizes an elliptic curve. In an elliptic curve system, an 
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ephemeral key pair is obtained by generating a secret integer, k and performing a point 
multiplication in the seed point Q to provide the ephemeral public key kQ, Similarly, the 
generation of a common ephemeral session key will require multiplication of a public key k*Q ? 
which is a point on the curve, with a secret integer kb of the other correspondent so that point 
5 multiplication is again required. 

A similar procedure is used to sign a message except that the sender applies his private 
key to the message. This permits any recipient to recover and verify the message using the 
senders public key. 

Various protocols exist for implementing such a scheme and some have been widely 
10 used. In each case, however 3 the sender is required to perform a computation to sign the 

information to be transferred and the receiver is required to perform a computation to verify the 
O signed information. 

yg In a typical implementation a signature component s has the form:- 

Yf s = ae + k (mod n) 

1 where; in an elliptic curve crypto system, 
r J P is a point on the underlying curve which is a predefined parameter of the system; 

k is a random integer selected as a short term private or session key; 
SX R « kP is the corresponding short termpublic key; 

^; a is the long term private key of the sender; 

2 ta Q ~ aP is the senders corresponding public key; 

^ e is a secure hash 4 such as the SHA-1 hash function, of a message m and the short term 

public key R; and 

n is the order of the curve. 

The sender sends to the recipient a message including m ? s s and R and the signature is 
25 verified by computing the value R 1 ~ (sP-eQ) which should correspond to R. If the computed 
values correspond then the signature is verified 

Li order to perform the verification it is necessary to compute the point multiplications to 
obtain sP and eQ, each of which is computationally complex. Where the recipient has adequate 
computing, power this does not present a particular problem but where the recipient has limited 
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computing power, such as in a secure token or a "Smart card " application, the computations may 
introduce delays in the verification process. 

Key generation and signature protocols may therefore be computationally 
intensive. As cryptography becomes more widely used there is an increasing demand to 
5 implement cryptographic systems that are faster and that use limited computing power, such as 
may be found on a smart card or wireless device. 

Elliptic curve cryptography (ECC) provides a solution to the computation issue, ECC 
permits reductions in key and certificate size that translates to smaller memory requirements, and 
significant cost savings. ECC can not only significantly reduce the cost, but also accelerate the 
10 deployment of smart cards in next-generation applications. Additionally, although the ECC 
algorithm allows for a reduction in key size* the same level of security as other algorithms with 
O larger keys is maintained. 

y§ However, there is still a need to perform fester calculations on the keys so as to speed up 

Yf the information transfer while maintaining a low cost of production of cryptographic devices. 

1 So Computing multiples of a point on an elliptic curve is one of the most frequent 

_n computations performed in elliptic curve cryptography. One method of speeding up such 
= m computations is to use tables of precomputed multiples of a point This technique is more useful 
m when a point is known beforehand. However, there are cases when multiples of previously 
f*; unknown points are required (for example, in ECDSA verification). Thus there is a need for a 

2(t j system and method for facilitating point multiplications. 

SUMMARY OF THE INVENTION 

In general terms, the present invention represents the scalar k as a combination of 
components ki and an integer X derived from an endomonphisim in the underlying curve, 
25 The method is based on the observation that, given an elliptic curve (EC) having complex 

multiplication mapping over a finite field, there is an X, which is the solution to a quadratic, for 
which the complex multiplication mapping is equivalent to multiplying a point Q by X. It will 
often be less computationally expensive to compute XQ via the complex multiplication map, 
compared to treating X as a integer and performing the EC multiplication. In practice, point 



3 



multiplication by other scalars (not just X) is required. It is also shown how the multiplication 
mapping may be used to compute other multiples of the point. 

In accordance with this invention there is provided a method for accelerating 
multiplication of an elliptic cun/e point Q(x,y) by a scalar k, the method comprising the steps of: 
5 selecting an elliptic curve over a finite field F such that there exists an endomorphism i}/, where 
V(Q) = for all points Q(x,y) on the elliptic curve; and 

using smaller representation ki of the scalar k in combination with the mapping y to compute the 
scalar multiple of the elliptic curve point Q. 

10 BRIEF DESCRIPTION OF THE DRAWINGS 

These and other features of the preferred embodiments of the invention will become more 
O apparent in the following detailed description in which reference is made to the appended 

drawings wherein: 
H J Figure 1 is a schematic diagram of a communication system; 

15Q Figure 2 is a flow chart showing the steps of implementing a first embodiment of the 

H present invention. 

3 Figure 3 is a flow chart showing the steps of providing parameters required to implement 

Sg the method of Figure 2. 

im DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS 
N * For convenience in the following description, like numerals refer to like structures in the 

drawings. Referring to Figure 1, a data communication system 10 includes a pair of 
correspondents, designated as a senderl2, and a recipient 14, connected by a communication 
channel 16. Each of the correspondents 12,14 includes a cryptographic processor 18,20 

25 respectively that may process digital information and prepare it for transmission through the 
channel 16 as will be described below, Each of the correspondents 12,14 also includes a 
computational unit 19,21 respectively to perform mathematical computations related to the 
cryptographic processors 18,20. The processors 18, 20 maybe embodied in an integrated circuit 
incorporated in the processor or may be implemented as instructions encoded on a data carrier to 
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implement a predetermined protocol in conjunction with a general purpose processor. For the 
purpose of illustration it will be assumed that the correspondent 12 is in the form of a smart card 
having a dedicated processor 1 8 with relatively limited computing power. The processor 20 may 
be a central server communicating with the card by channel 16 and channel 16 may be a wireless 
5 communication channel if preferred. 

The cryptographic processors 18 implement an elliptic curve cryptographic system, of 
ECC, and one of the functions of the cryptographic processor 18 is to perform point 
multiplications of the form k*Q, where k is an integer and Q a point on the underlying elliptic 
curve, so that they may be used as a key pair k, kQ in a cryptographic scheme. As noted above, 
10 cryptographic computations such as the multiplication of an elliptic curve point by a scalar value 
are computationally expensive, 
o A method for accelerating scalar multiplication of an elliptic curve point Q(x,y) is shown 

/5C in figure 2 and indicated generally by the numeral 50. The subject algorithm increases the speed 
W at which the processors 1 2 can for example sign and verify messages for specific classes of 
if !; elliptic curves. The method is based on the observation that given the general equation for an 
H elliptic curve E: 

s" y 2 + aixy + a 3 y = x 3 + a2X 2 + a4X + a^ (1) 

y over a finite field, exemplified as F q (q is a prime power) and when there exists an 
N endomorphism where y(Q) - ^"Q for points Q(x,y) on the elliptic curve, then 
2fji multiplication of the point Q by an integer k may be accelerated by utilizing combinations of 
^ smaller representations kj of k in combination with the mapping The mapping \|i also allows 
precomputation of group elements and combinations thereof, which maybe used in subsequent 
calculation of kQ. 

Referring now to figure 2 > a flow chart of a general embodiment for accelerating point 
25 multiplication on an elliptic curve, is shown by numeral 50. The system parameters are first 
selected As an initial step an underlying elliptic curve E is selected to have certain 
characteristics. In a first embodiment of the invention the generalized elliptic curve (1) may be 
expressed in the following form: 

E;y 2 ==x 3 + bmodp; where p is a prime. (2) 
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Firstly, the modulus p can be determined such that there is a number, y where y e F p (F p 
is the field of size p consisting of all integers mod p)» and y 3 = 1 mod p (a cube root of unity). If 
for example p - 7, then y = 2, since 2 3 mod 7 "1 , Such a y does not necessarily exist for all p, 
and therefore this must be taken into consideration when choosing the value of p. Typically, the 
5 chosen p should be at least 160 bits in length for adequate cryptographic strength, 

After the curve E has been selected, a mapping function \j/ is determined. The mapping 
function y: (x, y) -> (yx, y), simply maps one set of points on the curve to another set of points 
on the curve. There exists an integer X such that \|/(Q) = X-Q for all points Q(x,y) of interest on 
the elliptic curve, E. This integer X may be found by noting that X 3 sl mod n, where n is the 
10 number of points on the elliptic curve E over F p i.e. the number of points on E(F P ). There may 
exist more than one solution for X in ^ 3 s 1 mod n, but only one of those solutions will satisfy the 
2 mapping function \|/. It is important to note that since y 3 mod p = 1, both Q and \|/{Q) satisfy the 
equation for E. Therefore, instead of having to perform lengthy calculations to determine the 
results of multiplication by X, it can be done very efficiently using the results of the mapping 
151 function so that multiplication by X can be done very efficiently. 
m A seed point Q is selected and the system parameters E, p, Q, X, \j/(Q) ? and y are stored in 

O the card 1 2> as indicated at 52, at manufacture time for use by the cryptographic processor 1 8. 
fl To implement a cryptographic procedure such as encryption, key agreement or signature it is 
2f necessary to select an integer k for use as an ephemeral private key k and generate a 
2<t corresponding public key kQ. 

The value of k may be expressed as: - 

k = (ko + M-)modn (3) 
where n is the number of points on E(F P ) and ko and ki are integers. The point k*Q then 
becomes: 

25 k-Q = (koQ + kiA.Q)modn (4) 

For some cryptographic operations the value of k may be chosen at random and in these 
cases, rather than select k it is possible to select values for ko and ki at random, having a length 
of [logz (n)]/2 not including sign bits, (i,e* the length of the kfs are chosen to be at least one half 
the length k) and then calculate the value for k using equation (3). 



Having selected the values of K, ki as indicated a 54 in figure 2, the right side of equation (4) 
can be calculated quickly using an algorithm analogous to the "Simultaneous Multiple 
Exponentiation" as described in the "Handbook of Applied Cryptography" (HAC) by Menezes 
et. aL(Algorithm 14.88) and indicated at 56. For convenience the algorithm is reproduced below. 
5 It may be noted that in an additive group exponentiation is analogous to addition, thus replacing 
the multiplication in the algorithm with addition, yields the following: 

Algorithm 1 Simultaneous Multiple Addition 

10 INPUT; group elements go, gi, ...,gM and non negative t-bit integers e 0? ei, ...,eM- 
OUTPUT; goeo + gjei + . . . + gweu. 

stepl • Precomputation. For i from 0 to (2* - 1): 

lftf where i -(im 10)2 

JS step2. A 0 

(7| step3. For i from 1 to t do the following: 

O step4. Return (A) where A " goeo + giei + . . . + gM«M 
2(H; * 

:L Applying this algorithm to equation (4) it can be seen that there are two group elements, go, 

CJ gi namely Q and XQ, so that 1 = 2 and two integers e 0> ei namely kojci. The algorithm permits 

s,i precomputation of some of the values and initially Gi is precomputed* The results of 

2p precomputation of G, with / - 2 is shown in table 1. 
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After performing a point addition to construct the point: Q + \|/(Q). It is possible to fill in 
30 table 1 with the computed elements to yield table 2. These elements may be pre-computed and 
stored in memory as shown at step 58 in figure 2. 
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'able 2. 



Before step of the algorithm can be performed, G Jt has to be determined and accordingly I] 
through l t have to he found as indicated at 60, A notional matrix or combing table may be 

5 constructed using the binary representation of Iq. If, for example, ko = 30 and ki = 1 0, then t has 
the value five since the maximum number of bits in the binary representation of ko through ki is 
five and the notional matrix constructed from their binary representation is shown in Table 3. I, 
is determined by the number represented in the I th column where the first row contains the least 
significant bit, the second row contains the next significant bit, etc. Therefore it can be seen 

lOM from table 3 tbat Ii - 1 2 - (1 1) = 3, Is = (01) *1 , 14 =3, and I 5 0. 
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TableS 



p All the components needed to complete the algorithm are available and the iteration of step 

1 5 three is performed as shown at 62. 

Initially A «- O andi is set to 1. 

Ii - Ii which from table 3 is equal to 1 . G, t is therefore Gi which from table 2 is Q. The 

value of A from the iteration for I = 1 is therefore O + Q = Q. 

For the next iteration where i = 2 the initial value of A is Q so A <- Q+Q = 2Q 
20 Ii = h = 3 from table 3. G 7j therefore equates to G 3 from table 2 which is Q+\j/(Q). 

A + G h therefore is computed as 2Q+Q+\|/Q = 3QH-\pQ. 
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The iterations continue for each value of i set out in table 4 until after the 5 iteration the 
value for koq = k, XQ, i.e. kQ is computed. 
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7Q + 2y(Q) 
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15Q + 5 V (Q) 
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30Q+10y(Q) 



Tahle4 



5^ Each iteration requires a point doubling (A+A) and a point addition (A+ Oj ) although in 

*f some cases the value of G J( may be O that will reduce the computation. 

Thus it may be seen that this method will require a number of point doubles equal to 
p max {log2(kj)} , and almost as many point additions. The number of point additions can be 
ft reduced using windowing (Alg. 14,85 HAC) and exponent recoding techniques. Since the value 
1Q of i and C\ can be preeomputed, the point additions are easily performed by retrieving the 
5[ appropriate precomputed element Gt from table 2. Once kP has been computed, it may be used as 
the correspondents 12 ephemeral public key in encrypting or signing transmissions over the 
channel 16* 

^ To summarize, for cryptographic operations like encryption and DifHe-Hellman, 

IS signature, an integer k is required with a corresponding public key kQ, computed. The values ko 
and ki are chosen at random, each having a length one half the length of n and the term koQ - 
k^Q generated using a suitable algorithm. When the k's are chosen in this way, the method 
seems to be as secure as the random generation of k itself Of course it is possible to choose the 
k/s to have fewer bits in order to improve efficiency, 
20 In the above technique, the method of writing k^to+^X bi conjunction with simultaneous 

combing achieves a speed up of the simultaneous multiple addition algorithm, The technique of 
writing k^ko-Hq A, may also be used with the scalar multiplication techniques to advantage, 
namely with winding, combing ..etc. 

9 



For some mappings it is also possible to use more than two sub k>s. It is possible for 
some \|/'s to write k=k 0 +k l X+k 2 X 2 allowing the value of k to be computed by applying the 
simultaneous multiple addition algorithm. 

In a second embodiment of the invention a different form of the generalized elliptic curve 

5 equation (1) is used, namely: 

y 2 = (x 3 - ax) mod p (5) 
Once again, p will be a prime number having at least 160 bits. For this type of curve, the 
properties required for y are different. It is now required to find a value such that 
y 2 = -1 mod p. A change in the property of y requires a different mapping function y' to be used, 
10 In this embodiment the mapping takes the form y 1 : (x, y) -> (-x, yy). If (x,y) is on the curve, 
then H/'(x,y) is also on the curve. In this case A, 4 s 1 mod n (n is still the number of points on 
I! E(F P )), and therefore X can be calculated. The mapping ^(Q) = ^'Q is performed as before and 
once again multiplication by X can be done very efficient The equation for kin 

2 this embodiment is the same as in the first embodiment and is represented by: 
iff k~Q£Q + k\X)modn (6) 

UJ This equation is the same as in the previous embodiment, having only two group elements- Thus 
ri using the group elements Q and Q+ y(Q) in the algorithm 1 , the point k'Q may be calculated. 
P: 1 This computation will require a number of point doubles equal to max {log^)} , and a similar 
SI number of point additions. As described earlier the number of point additions can be reduced 
2(h' using windowing and exponent recoding techniques. 

This method applies to other elliptic curves, so long as there exists an efficiently 
computable endomorphism, 

The above embodiments assume that k can be chosen at random and therefore k* and k 3 
can be selected instead and determine k. For cryptographic protocols, where it is not possible to 
25 choose k, it is first necessary to find ko, ki of the desired "short" form from the given value of k 
such that k = (ko + k } X) mod n. In some cases, more than two k's can be used to advantage. 

As may be seen in the embodiments described above when a point is known beforehand, 
tables can be built to speed multiplication. However, there are cases when multiples of 
previously unknown points are required (for example, this can occur in ECDSA verification) and 
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it is then necessary to take the value of k as provided and then determine suitable representations 
for kj, 

Thus in a third embodiment, system parameters and a value k is provided, the point Q, 
the required multiple k, and the complex multiplication multiple X are known. It is necessary to 
5 determine the "short" kfs from the value for k, which is predetermined. A method for doing this 
described as follows and illustrated in the flow chart of figure 3. As a pre-computation (not 
requiring k) we compute two relations: 

ao + bo^ = 0 mod n 

ai + b\X s 0 mod n 

10 such that ai and h are numbers smaller than n. It is preferable that ai and bj are as small as 

possible, however, the present method has advantages even when ai and b* are not minimal. The 
O pair, a, and b*, where aj and b\ are both small, can be viewed as a vector, Ui with a small 
5 Euclidean length. Typically the method described below produces ko and ki having 
jr: representations one half the size of the original k. 
1 §3 In the present embodiment, kQ can be computed efficiently by utilizing precomputed, 

i short vector presentations to obtain an expression of the form: 
U koQ + J-kiQ 

03 This is accomplished by using precomputed vectors to derive fractions^ and/i that do 

f S not require knowledge of k. A vector z is generated from the combination of fractions^, and/i 
2fP and k. The vector z is used to calculate a second vector v* where v'= (vo',Vi ') and the value of 
kQ calculated as 

vo'Q + WQ (8) 
The method of achieving this solution is described below in greater detail. 

To produce small ai and bu it is possible to make use of the L 3 - lattice basis reduction 
25 algorithm (H AC p, 1 1 8), which would directly result in short basis vectors. However, in this 
preferred embodiment the simple extended Euclidean algorithm is employed on the pair (n, X). 
The extended Euclidean algorithm on (n, X) produces linear combinations c*n + diX « r l9 where 
the representation of ri(e.g + bit-length) decreases and the representation of q and d\ increases 
with L 
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The two smallest values of |(ds, rj )| resulting from using the extended Euclidean 
algorithm are saved. The size of these vectors are measured with the squared Euclidean norm 
j(di, r,- )| = d* + Ti 2 . The terms in these minimal relations are denoted d 0? f 0 and d 3 , fj ♦ And will 
typically occur in the middle of the algorithm. Even if the minimal relations are not retained, 
suboptimal relations may still give the method an advantage in the calculation of point multiples. 

The values of aj and bj are constructed by defining ao = - f 0 , bo " d 0 and = -r 15 

bi = d g allofwhichmaybeprecomputed. 

The next task is to find a small representation for the multiple k. 

Given the computation of ao,b 0 and a^bj it is possible to designate the vectors u P? ul ? 
where = (ao, bo) and Ui = (at, bi). These vectors satisfy ai +b{k - 0 (mod n). The 
multiplication of the group elements Q by the vector v = (vq, vi) is defined as (v 0 + v^)Q. Since 
a,- +b& - 0 (mod n), u<>R = UiR = 0 for any group element R. Hence for any integers zq and Zi, 
v'R - (v - ZoUo - ziUi)R for any group element R. 

Integers z<> and z\ may be chosen such that the vector v' = v - zoua - ZiUj has components 
that are as small as possible* Again, this method will have an advantage if the components of v* 
are small, but not necessarily minimally so. 

The appropriate Zo and zi are calculated by converting the basis of v into the basis {no, 
Ui}, The conversion between basis involves matrix multiplication. To convert the vector v - (vo, 
Vi) from the {uo> ui} basis to the standard orthonormal basis {(1,0),(0,1)} , 

To convert in the other direction, from the standard orthonormal basis {(1,0),(0,1)} to the (u 0j Hi) 
basis, the multiplication is simply by the inverse of M, 



v M " v {[x m) inverse{M) = v {(l)OMOiI)) \ 



Since the vector v = (k, 0) has a zero component, the bottom row of inverse(M) is not 
required, and therefore to convert to the {no, ui} basis only the fractions 
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and 

5 are needed. 

The fractions^ and/i may be precompiled to enough precision so that this operation 
may be effected only with multiplication. It should be noted that the computations leading to 
these fractions do not depend upon k, therefore they can be computed once when the elliptic 
curve is chosen as a system parameter, and do not need to be recalculated for each k. Similarly 
1 Orj the vectors v, Uo and u x may be precomputed and stored 
iJ 2 Once a value of k is selected or determined the value of kQ may be computed by first 

y calculating z = (zo, zj), where z is defined as (zo, zi) = (round(kf 0 ), round(kfO). 
El Other vectors near to z will also be useful, therefore rounding could be replaced with floor or 
H ceiling functions or some other approximation. 
1 <T Once a suitable z has been determined, an efficient equivalent to v (k,0) is calculated by 

g v ' ^ (vq\ v^) = v - zoiio -ZiUi- The phrase "efficient equivalent" implies a vector V such that v'P 
H - vP and v* has small coefficients. The value kQ is then calculated as v 0 'Q + v AQ. This value 
r2 can be calculated using simultaneous point addition as described above, with enhanced 

efficiency obtained from the use of non-adjacent form (NAF) receding as described above and as 
20 described in H.A.C. 14.7 at page 627, Thus, even where k is predetermined, values of ko and ki 
can be computed and used with the mapping function to obtain a value of kQ and hus he key pair 
k,kQ. 

For the case where k is to be separated into 3 portions k = ko + kj X + kaX\ small vectors 
can be obtained from L 3 -row-reducing 
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A small vector equivalent (three-dimensional row) can be obtained in a similar way to the 
two-dimensional case. 

Using these methods to determine the value of k'Q greatly reduces the processing power 
required by the cryptographic processors 12. It also increases the speed at which these repetitive 
calculations can be done which, in turn, reduces the time to transfer information. 

It will be appreciated that once the scalar multiple k has been represented in terms of 
shortened components k = ko + ki?i + k^ 2 + . . -Wi A,™" 1 , other options for efficient elliptic curve 
scalar multiplication may be used in place of or in conjunction with the simultaneous multiple 
addition algorithm. These options include windowing (fixed and sliding), combing, bit recoding 
and combinations of these techniques* 

One particularly beneficial technique permits tables built for one component of the 
multiplication* say ko f to be reused for other components ki etc. This is accomplished by 
transforming the computed table elements by applying the mapping y as required. 

As a further exemplification, an embodiment where k can be recast as k = ko + kiX, + , 
where k has m-bits and kj have roughly m/3 bits is described below. 

Once the components ki have been determined, they may be recoded from the binary 
representation to the signed binary representation having less non-zero bits* This receding can 
take the Non- Adjacent-Form (NAF), where every 1 or -1 bit in the representation if ki is non- 
adjacent to another non-zero in the signed binary string. This recoding is described in H.A.G 
14.7 p. 627. 

Once each kj has been recoded, a table can be constructed to aid in computing k t XP . 

A NAF windowing table precomputes certain short-bit length multiples of XP . The 
width of the window determines the size of the table. As ki has been recordedto have no adjacent 
non zeros, odd window widths are suitable* A 3-bit wide NAF window would contain 



The recoded ki values are built by concatenating these windows, and padding where 
necessary with zeros (H.A.C., p. 616), 
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The required number of additions can be reduced with use of this table, since it is 
necessary to add or subtract an EC point only for every window encountered instead of for every 
non zero bit. 

Initially therefore this technique is applied to the computation of kJP. 

The table built for the koP calculation can be applied to the k { X P calculation if the table 
elements are mapped with the \y mapping using the operator y . Similarly, k 2 Z 2 P can be 
accelerated by using the table built for kef, but mapping the table elements with y 2 . 

In applying the sliding window technique to the component only one set of doublings 
need be performed. 

To illustrate this example of a preferred embodiment the following example will be used: 
Ifk = [l01101011101]2 + [111010101101]2 K 
then recoding 

k - [10-100-10-1 00-101] + [1000-10-10-10-101] X, 
= k£+k{X 

A 3-bit window table on P is precomputed containing 1*P, [10-1]»P, [101>P. This 
requires two EC additions, and two EC doublings. 
After this, kP can be calculated as 
kP - [10-100-10-100-101] P + [1000-10-10-10-101] • X? 
• by adding/subtracting elements from the table. 
This can be done using an accumulator A as follows: 
A*-0 ; initialize 

A V (1 # P) ; consuming the top bit of k F 0 

A«- 2A ; double A 

Af- 2A 

A [1 0 -1] P ; consuming the top 3 bits of kl 

A+- 2 4 A ; 

A - = [101 ] y P ; consuming a 3 bit window of k{ 

A<- 2 A ; double A 



A -**[101]P 
A*- 2 4 A 
A - = [101]i|/P 
A<- 2 2 A 



; consuming 3 bits of fc[ 



; consuming 3 bits of fc( 
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A — [10-1] P 



; consuming the last of 



A + = yP 



; producing kP T 



It will be recognized from the above example that the windows in ko and kt need not be 
aligned This is evidenced by the fact that the accumulator is doubled between computations of 
10 the windows in ko and the computations of the windows in k.\ 9 indicating a shift of window 
_ between evaluating koP and kiF. 

5 In summary, the previously described technique is as follows. Given an elliptic curve E 

ffs and an endomorphism \|/, there corresponds an integer X such that ?iQ=ty(Q) for all points QeE. 
N* Select an integer ra and compute an equivalent number m of "short basis vectors" bi, b2, - ■ . ? b m „ 
l£L Each such basis vector coiTesponds to an integer, and each such integer is divisible by the 
m number of points n - # E(F p m ) (i*e. the number of points). Now, given an integer k, (0 < k < n)» 
O we write k = £ Jt, • X , where the ki*s are chosen to be "short' \ This is done by finding the 
h** difference between a certain vector (which represents k) and a nearby vector in the lattice 
fi generated by bi 4 b2* . . - ,bm- 
2#^~ The following embodiment explicitly describes an application of the previously described 

technique (endomorphism and basis conversion and "Shamir's trick") to elliptic curves defined 
over composite fields. In particular, we describe an application to curves E(F p m ) where p is an 
odd prime is described. The following embodiments exemplify techniques for such curves. 



25 (x p >-f) and E'A 3 (Fp m ) where A,B<=P P . 

In this case, it is known that the Frobenius map satisfies the \jr - ty + p - 0, where t ~ 
p+1- #E(F p m ). 

It follows that X 2 ' tt, 4-p 0 mod n and so X 2+I - pV - 0 mod n. 



This technique is described in the case where the map \[/ is the Frobenius map tyO^y) " 



Note that the vectors; 



(0, 


o, 


0,... 


0, 1, 


-t. p) 


( 






1,-t, 


P. 0) 


(1, 


-t, 






...,0) 


(-t, 


p 5 


0,0, ... 




...A i) 


<p, 


o, 


o,o,»- 


o, 


1,-t) 



1 0 consist of m "short" basis vectors of the vector space Q n . It follows that to compute k>Q 

on such a curve we can proceed using the vectors bi a b2- . *b m and the technique described 
O previously. 

In the above embodiments it will be appreciated that k,XQ can be obtained from y(kQ) is 
» the mapping is more efficient than addition* 
1 5o hi a further embodiment, the above methods are used to verify a digital signature on a 

r* message. A sender sends a message m, a signature component s, and a short term public key 
s R=kP. As indicated above, in a typical digital signature protocol, the signature component s is 
iS generated using the formula s = ae + k. The value a is a long term private key of the sender, and 
H e is a hash of the message m. 
2Qe*% Verification requires computing the value sP - eQ which should correspond to R, where 

H= Q = aP is a long term public key of the sender. This is the case since k = s - ae. 

Accordingly, Algorithm 1 may be applied to compute a sum go^o + giei of scalar 
multiples of two group ^hment$ go and g\, where the scalars are s and -e and the group elements 
are P and Q. A fiirther improvement is obtained by using the NAF as above. 
25 For ease of explanation, the method will be illustrated for computing aP + pQ. In the 

preferred embodiment of verifying a signature, a = s and P - -e, 

In this case, it may no longer be possible to reuse tables built for one component of the 
multiplication for other components, unless the relationship between the points P and Q is known 
to the verifier. Usually, the verifier knows P and Q, but not the scalar a that related P and Q (Le. 
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Q = aP), In this case, it is necessary to use a table for each of P and Q, Then a sliding window 

method may be used by adding/subtracting elements from the tables. 
The following example illustrates this embodiment; 
ifcc = [101101011 101] 2 andp = [111010101101]^ 
fhcnk^IlOllOlOlllOlb + [U1010101101]2 a, 
and recoding a = [10-100-10-100-101] 2 and p - [1000-10-1 0-10-101] 2 , 
A 3-bit window table on P and a 3-bit window table on Q are precomputed containing 

1-P, [10-1>P. [101]*P and 1-Q, [10-1J-Q. [101]»Q respectively. This requires two EC additions, 

and two EC doublings for each table. 

After this, kP can be calculated as 

kP= aP 4- 0Q~ [10-100-10-100-101] P + [1000-10-10-10-101] • Q 
by adding/subtracting elements from the tables. 
This can be done using an accumulator A as follows: 



A<-0 


; initialize 


A+= 1*Q 


; consuming the top bit of P 


A*- 2A 


; double A 


A 4- 2 A 




A+- [10-1]P 


; consuming the top 3 bits of a 


A«- 2 4 A 


> 


A- = [101]Q 


; consuming a 3 bit window of p" 


A*- 2A 


; double A 


A - = [101]P 


; consuming 3 bits of p 


A<- 2 4 A 




A - = [101]Q 


; consuming 3 bits of 0 


A<- 2 2 A 




A - = [10-1]P 


; consuming the last of ot 


A + = Q 


; producing kP. 
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The signature is accepted as originating from the sender if the calculated value of kP is 
equal to the value of R received with the signature. 

Again, it will be appreciated that the windows need not be aligned and that shifting of the 
windows produces a double of the accumulator for each bit shift of the window. 

Although the invention has been described with reference to certain specific 
embodiments, various modifications thereof will be apparent to those skilled in the art without 
departing from the spirit and scope of the invention as outlined in the claims appended hereto. 
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